Soru

Zorluk: ZorWireless Security and Authentication

A systems technician is deploying a wireless network across several retail store locations. Management mandates that store associates log in using their individual Active Directory credentials. To protect against rogue access points, client handhelds must validate the RADIUS server's identity using a digital certificate. However, management explicitly prohibits the deployment and maintenance of individual client-side digital certificates due to administrative overhead. Which of the following wireless authentication configurations should the technician implement?

  1. PEAP (Protected Extensible Authentication Protocol)Cevap
  2. B
    EAP-TLS (Extensible Authentication Protocol-Transport Layer Security)
  3. C
    WPA3-Personal utilizing SAE (Simultaneous Authentication of Equals)
  4. D
    Captive Portal with MAC address filtering

Cevap

PEAP (Protected Extensible Authentication Protocol) provides centralized Active Directory user authentication while requiring a digital certificate only on the RADIUS server.
The selection specifying PEAP (Protected Extensible Authentication Protocol) is correct because PEAP establishes an encrypted TLS tunnel using a digital certificate hosted strictly on the RADIUS authentication server. This allows client devices to verify the server's identity to prevent rogue access point attacks, while enabling employees to authenticate using their standard Active Directory credentials (via MS-CHAPv2 inside the tunnel) without requiring client-side certificates.

Adım Adım Çözüm

1
Analyze authentication account requirements.
The requirement for individual Active Directory user accounts necessitates an enterprise 802.1X authentication framework integrated with RADIUS.
Personal authentication modes (PSK or SAE) rely on shared passphrases rather than domain user credentials.
2
Evaluate certificate requirements for server and client endpoints.
The client must authenticate the server (requiring a server certificate), but clients must not require individual certificates.
This constraint eliminates EAP-TLS, which mandates dual-sided (server and client) digital certificate deployment.
3
Select the EAP type matching the certificate and user authentication criteria.
PEAP establishes a secure TLS tunnel using only the server's certificate, through which internal password-based methods (such as MS-CHAPv2) carry the domain credentials.
PEAP satisfies both requirements: server validation via certificate and zero client-certificate overhead.

Anahtar Kavram

EAP Protocol Differences in 802.1X Enterprise Wireless Security
Tahmini Süre:2m 0s
Bu soruyu puanla